An investigation of phishing awareness and education over time: When and how to best remind users

Benjamin Maximilian Reinheimer, Aldag, Lukas,, Peter Mayer, Mattia Mossano, Reyhan Duezguen, Bettina Lofthouse, Tatiana Von Landesberger, Melanie Volkamer
2020
Security awareness and education programmes are rolled out in more and more organisations. However, their effectiveness over time and, correspondingly, appropriate intervals to remind users' awareness and knowledge are an open question. In an attempt to address this open question, we present a field investigation in a German organisation from the public administration sector. With overall 409 employees, we evaluated (a) the effectiveness of their newly deployed security awareness and education
more » ... ness and education programme in the phishing context over time and (b) the effectiveness of four different reminder measures -administered after the initial effect had worn off to a degree that no significant improvement to before its deployment was detected anymore. We find a significantly improved performance of correctly identifying phishing and legitimate emails directly after and four months after the programme's deployment. This was not the case anymore after six months, indicating that reminding users after half a year is recommended. The investigation of the reminder measures indicates that measures based on videos and interactive examples perform best, lasting for at least another six months.
doi:10.5445/ir/1000122566/pre fatcat:o7evy56zvre7leqv2nbl6g2j4i